Privacy and Data Policy

Last updated April 13, 2023

Summary: The Python Software Foundation ("PSF") only collects the information necessary to register you for PyCon US and to provide you access to the PyCon US content and services. Registrant contact information is NOT shared with third parties without your explicit opt-in consent.

If you submit a talk, tutorial, or other content, then your name will be publicly associated with your personal content for purposes of giving you credit for your contribution to the conference and to maintain historical records.

You may opt in to getting email messages about the PyCon US conference, and you may opt-in to sharing basic contact information with sponsors of PyCon US. Choosing not to opt in will in no way detract from your ability to attend or engage with PyCon US.

After PyCon US is over and we have fully discharged all of our responsibilities, we will delete any personal information that is not required to preserve publicly-available educational materials or to maintain legal records.

1. WHO IS RESPONSIBLE FOR THE PERSONAL INFORMATION THAT WE COLLECT?

For the purpose of data protection laws, the Python Software Foundation ("PSF") is the data controller in respect to the personal information that we collect and use as part of our business activities. As the data controller, we control, manage, and dictate the purpose for which your personal information is used and how we use your personal information for our business activity.

If you choose to provide your personal information to other parties during PyCon US, including sponsors, then their data privacy policies apply to the data that you give to them.

2. WHAT PERSONAL INFORMATION DO WE COLLECT?

The types of personal information that the PSF may collect include, but are not limited to, the following:

  • Full name
  • Address
  • Phone numbers
  • Email addresses
  • Other contact information
  • Payment information
  • Company, firm, organization, agency, or other entity information
  • Photograph
  • Biography
  • Preference information, such as communications that you receive from us
  • Dietary preferences and requirements
  • Information that you provide for the purposes of attending meetings, events, webinars, and other programs
  • Any other information relating to you (or other individuals) which you may provide to us

If you provide personal information to us regarding or related to a third party, then you confirm that you have the consent of the third party to share such personal information and that you have made the information in this Privacy Policy available to the relevant third party.

3. USE OF THIRD PARTY SERVICES

The PSF uses some third party services to assist with producing PyCon and operating online services supporting PyCon. Specifically, we use:

  • Hubilo (https://hubilo.com/) to provide online content management and streaming services for PyCon US. Hubilo has its own Terms of Service (https://hubilo.com/terms-of-use/) and Privacy Policy (https://hubilo.com/privacy-policy/), which apply to your use of the Hubilo service to access PyCon US online content. To the extent that Hublio's terms are more restrictive than this policy, the more restrictive terms will apply. Hubilo's use of PyCon attendee data is subject to the Data Processing Agreement between Hubilo and PSF.

  • ShareMy.Health to verify attendees' COVID status. We share your name and email address with ShareMy.Health to enable them to contact you to verify your test results. Your disclosure of personal information to ShareMy.Health is governed by their Privacy Policy (https://www.sharemy.health/privacy). 

  • CVent to manage attendee room assignments. We share your name, email address, affiliation, and address with CVent. CVent's use of this information is governed by the Data Processing Addendum between CVent and PSF. Your disclosure of personal information to CVent is governed by their Privacy Policy (https://www.cvent.com/en/cvent-global-privacy-policy). 

  • Heroku (Salesforce) to host the PyCon website. We store your registration information on Heroku servers. Their use of this information is subject to the Data Processing Addendum between Salesforce and PSF and the Salesforce Privacy Statement (https://www.salesforce.com/company/privacy/full_privacy/).

  • [Amazon Web Services (AWS) to host the PyCon website. We store your registration information on AWS servers. Their use of this information is subject to the Data Processing Addendum between AWS and PSF and the AWS Privacy Notice (https://aws.amazon.com/privacy/).]

4. SENSITIVE OR SPECIAL CATEGORIES OF INFORMATION

SENSITIVE INFORMATION

Some countries consider some personal information particularly sensitive or special. This may include Ethnicity, Nationality, Gender, and other demographic information. The PSF only collects this data when voluntarily given by the individual, and does not require it from any attendee. The PSF may use this information to create aggregated reports only; the PSF does not share any person's sensitive information with third parties.

WEBSITE USAGE INFORMATION

We collect information when you provide it to us, such as when you email us information, connect with us on social media, use the "contact us" feature, use the subscription feature located on our website, or when you engage in any other communication, recorded or otherwise communicated.

The PSF collects certain information automatically when you use the website, such as the IP addresses and domain names of visitors, browser type, history of pages viewed and other usage information about your use of the website. We collect this information for site administration purposes, such as to analyze this data for trends and statistics. We may share statistical or aggregated non-personal information about our users with advertisers, business partners, sponsors, or other third parties. This data is used to customize our website content and advertising to deliver a better experience to our users. Please see the section below on cookies for information.

COOKIES

As you browse the PyCon US website (and the sites of third party providers contracted to provide services), those sites may place cookies on your computer. The cookies used by the PyCon website are strictly functional cookies and have no marketing purpose. For any third party provider, please see that provider's cookie policy.

PRESENTER OR AUTHOR INFORMATION

If you choose to author a written resource, including a mailing list post, or speak at PyCon US (both live and recorded for further broadcasting), you may be required to provide minimal biographical information to associate with your presentation or materials. You agree that this information will remain publicly available for purposes of proper attribution of your work and maintenance of the historical record.

5. HOW DO WE OBTAIN YOUR PERSONAL INFORMATION?

As noted above, we collect information from you in the course of your use of the PSF website, products, and services. For example, we collect information from you when you subscribe to our mailing list. We collect information from you when you contact or communicate with us (including through the website, by email, or otherwise). We collect your personal information while monitoring the PSF website, products, and services. We gather information about you when you provide it to us, or interact with us directly, for instance engaging with staff or registering for an event. We may also in certain cases collect or receive information about you from other sources, such as third party companies.

6. HOW DO WE USE THE PERSONAL INFORMATION THAT WE COLLECT?

The PSF collects personal information for the following principal purposes. The list below will state the purpose and the reason for the purpose of collecting your personal information.

  • To provide the PyCon website to you
  • To enroll you for PyCon US-related mailings (opt-in only)
  • To register you for events, tutorials, and other services
  • To provide you with information about Python, PyCon US, and events within PyCon US
  • To allow you to connect with PyCon US sponsors (opt-in only)
  • To communicate with you and to respond to your questions, inquiries, or concerns
  • To administer and improve the PSF and PyCon US, including the websites, events, tutorials, and other services
  • To process your payment for the PSF services and events
  • To prevent and detect fraud
  • To protect and enforce our legal rights

We do this for our legitimate business purposes, and under certain circumstances, to perform a contract between you and us. We may request your consent in circumstances where a legal justification over and above legitimate interests is required by applicable law.

7. WHO DO WE SHARE YOUR PERSONAL INFORMATION WITH?

The PSF may share personal information with third parties engaged to assist the PSF in providing services to you or to carry out one or more of the purposes described above. These service providers are prohibited from using your personal information for any purpose other than to provide this assistance and are contractually required to protect personal information disclosed by the PSF and to comply with the general privacy principles described in this Privacy Policy. For example, we share your information with service providers, contractors and sub-contractors to help us provide the website, products, events, and services. For example, we may use a service provider to process payment information or provide analytics. When we use service providers, we provide limited access to your information so that such service provider can perform the tasks on our behalf.

The PSF also shares basic contact information (badge name, nickname provided at signup, email address, and country provided during registration) with sponsors if you have explicitly consented to having your contact information shared with those sponsors by permitting them to scan your PyCon badge. You may also choose to share additional information with specific sponsors via the PyCon dashboard.

The PSF reserves the right to disclose and/or transfer personal information to a third party, if the PSF has reason to believe that disclosing personal information is necessary to identify, contact, or bring legal action against someone who may be causing injury to or interference with our rights or property, other website users, or anyone else who could be harmed by such activities. Additionally, the PSF may disclose personal information in response to a subpoena, warrant, or other court order, or when we believe in good faith that a law, regulation, subpoena, warrant or other court order requires or authorizes us to do so, or it is required to respond to an emergency situation.

If you choose not to provide the PSF with your personal information, you may still visit some of the PSF website; however, you may be unable to access certain options, offers, and services.

8. TRANSFER OF PERSONAL INFORMATION ACROSS BORDERS

The PSF is a United States organization, headquartered in the United States. While we are not a global company, we may allow your personal information to be shared with third-party service providers based both within the United States and in other countries. This may entail a transfer of your personal information from a location within the European Economic Area to outside the European Economic Area, or from outside the European Economic Area to a location with the Economic European Area.

When we provide your personal information overseas, we do so in connection with providing information or services or as required or authorized under law. It is possible the overseas entities, which we share your information with, may not be subject to foreign laws that provide the same level of protection of information with, may not be subject to foreign laws that provide the same level of protection of information as your country of residence or employment, or may not be subject to any privacy obligations. Overseas entities may be required or compelled to disclose your personal information to a third party, such as an overseas authority. Where we transfer information outside of the European Economic Areas, we will implement appropriate measures to ensure that your personal information remains protected and secure in accordance with applicable data protection laws. For example, we will implement EU standard contractual clauses (as contemplated by Article 46(2) of the European Union's General Data Protection Regulation) between the PSF related entities that share and process personal data. Where our third-party service providers process personal data outside the European Economic Area in the course of providing services to us, our written agreement with them will include appropriate measures, usually standard contractual clauses. For more information about the measures in place, please contact us (see section below "Contacting the PSF with Questions, Concerns, or Complaints").

Unfortunately, the transmission of information via the internet is not completely secure. Although we use reasonable efforts to protect your personal information, we cannot guarantee the security of your personal information transmitted to our website and any transmission is at your own risk. Once we have received your personal information, we will use reasonable and appropriate procedures and security features to try to prevent unauthorized access.

9. YOUR RIGHTS, INCLUDING REMOVING, CORRECTING OR UPDATING PERSONAL INFORMATION

If you change your mind on how the PSF discloses or uses your information, or wish to access, correct or update personal information (such as your address), we will endeavor to correct, update or remove the personal data that you give us. Information that you have explicitly made available for unrestricted public access, such as having your name associated with a talk that you provide, may not be able to be deleted.

Citizens of California and Virginia, and citizens of countries in the European Union and European Economic Area may have further rights, including:

  • Right of Access to your Personal Information
  • Right to Rectify your Personal Information
  • Right to Erasure of your Personal Information
  • Right to Restrict the use of your Personal Information
  • Right to Data Portability
  • Right to Object to the Personal use of your Information
  • Right to Withdraw Consent
  • Right to Complain to the Relevant Data Protection Authority

If these rights apply to you and you wish to exercise those rights, please contact the PyCon US organizers.

10. HOW LONG WILL WE KEEP YOUR PERSONAL INFORMATION

We will keep your personal information for no longer than is necessary for the purposes for which the personal data are processed.

11. CONTACTING THE PSF WITH QUESTIONS, CONCERNS, OR COMPLAINTS

If you have any questions, concerns, or complaints about this Privacy Policy, please contact legal@python.org. You are entitled to make an anonymous complaint or inquiry in relation to this Privacy Policy or your privacy rights; however, we may require you to identify yourself if required by law or it is impracticable for us to deal with your matter otherwise.

We will acknowledge receipt of any complaint and will strive to provide you with a written response within 30 days of receipt of your complaint. There may be instances where this is not possible due to the circumstances under which the complaint was made, the content of the complaint, and the scope of the complaint. If this is the case, we will respond to your complaint in a reasonable and practical time.


Last update: April 13, 2023

**End of official Privacy and Data Policy**


Updates, 2023-04-13

We updated our privacy policy to be sure that we are as transparent as possible in how we handle your data, and explicitly make clear where that data is stored.

A full diff is shown below for review, but a legally non-binding summary of material changes are as follows:

  • The country you provided during registration will be provided to sponsors who scan your badge.
    • Reason: Ironically, this is to ensure that all parties are in compliance with the most up to date privacy laws.
  • We added an up-to-date list of third-parties data is shared with, for what purpose, and references to their data and privacy policies.
--- a/docs/us.pycon.org/Privacy-Policy.md
+++ b/docs/us.pycon.org/Privacy-Policy.md
@@ -1,4 +1,11 @@
-Summary: The Python Software Foundation ("PSF") only collects the information necessary to register you for PyCon US and to provide you access to the PyCon US content and services. Registrant contact information is NOT shared with third parties without your explicit opt-in consent.
+# Privacy and Data Policy
+
+Last updated [DATE]
+
+Summary: The Python Software Foundation ("PSF") only collects the information necessary to register you for PyCon US and to provide you access to the PyCon US content and services. Registrant contact information is NOT shared with third parties without your explicit opt-in consent.
 
 If you submit a talk, tutorial, or other content, then your name will be publicly associated with your personal content for purposes of giving you credit for your contribution to the conference and to maintain historical records.
 
@@ -14,29 +21,37 @@ If you choose to provide your personal information to other parties during PyCon
 
 ### 2\. WHAT PERSONAL INFORMATION DO WE COLLECT?
 
-The type of personal information that the PSF may collect include, but is not limited to the following:
+The types of personal information that the PSF may collect include, but are not limited to, the following:
 
 -   Full name
 -   Address
--   Phone Numbers
--   Email Addresses
--   Other Contact Information
--   Payment Information
--   Company, Firm, Organization, Agency, or other entity information
+-   Phone numbers
+-   Email addresses
+-   Other contact information
+-   Payment information
+-   Company, firm, organization, agency, or other entity information
 -   Photograph
--   Biographies
--   Preference Information, such as communications that you receive from us
--   Dietary Preferences and Requirements
--   Information that you provide to use for the purposes of attending meetings, events, webinars, and other programs
+-   Biography
+-   Preference information, such as communications that you receive from us
+-   Dietary preferences and requirements
+-   Information that you provide for the purposes of attending meetings, events, webinars, and other programs
 -   Any other information relating to you (or other individuals) which you may provide to us
 
 If you provide personal information to us regarding or related to a third party, then you confirm that you have the consent of the third party to share such personal information and that you have made the information in this Privacy Policy available to the relevant third party.
 
-### 3\. USE OF THIRD PARTY SERVICES
+### 3\. USE OF THIRD PARTY SERVICES
+
+The PSF uses some third party services to assist with producing PyCon and operating online services supporting PyCon. Specifically, we use:
+
+-   Hubilo () to provide online content management and streaming services for PyCon US. Hubilo has its own Terms of Service (/) and Privacy Policy (), which apply to your use of the Hubilo service to access PyCon US online content. To the extent that Hublio's terms are more restrictive than this policy, the more restrictive terms will apply. Hubilo's use of PyCon attendee data is subject to the [Data Processing Agreement](https://uploads-ssl.webflow.com/61f2936079ce67606fdade16/63a9c7122eee221c3c616e90_Hubilo%20_%20Data%20Processing%20Addendum%20%5BDPA%5D%20-%20Updated.pdf) between Hubilo and PSF.
+
+-   ShareMy.Health to verify attendees' COVID status. We share your name and email address with ShareMy.Health to enable them to contact you to verify your test results. Your disclosure of personal information to ShareMy.Health is governed by their Privacy Policy (). 
+
+-   CVent to manage attendee room assignments. We share your name, email address, affiliation, and address with CVent. CVent's use of this information is governed by the [Data Processing Addendum](https://www.cvent.com/sites/default/files/files/2022-09/CVENT%20CUSTOMER%20GDPR%20DPA%20C2P%20SCC%20%2B%20UK%20IDTA%20%28version%205.26.2022%29_0.docx) between CVent and PSF. Your disclosure of personal information to CVent is governed by their Privacy Policy (). 
 
-The PSF uses some third party services, notably Hubilo () to provide online content management and streaming services for PyCon US. Hubilo has its own terms of service and privacy policy, which apply to your use of the Hubilo service to access PyCon US online content.
+-   Heroku (Salesforce) to host the PyCon website. We store your registration information on Heroku servers. Their use of this information is subject to the [Data Processing Addendum](https://www.salesforce.com/content/dam/web/en_us/www/documents/legal/Agreements/data-processing-addendum.pdf) between Salesforce and PSF and the Salesforce Privacy Statement ().
 
-To the extent that any part of the Hubilo Terms of Service (/) or Privacy Policy () is more restrictive than this policy, the more restrictive terms will apply.
+-   [Amazon Web Services (AWS) to host the PyCon website. We store your registration information on AWS servers. Their use of this information is subject to the [Data Processing Addendum](https://aws.amazon.com/blogs/security/aws-gdpr-data-processing-addendum/) between AWS and PSF and the AWS Privacy Notice (https://aws.amazon.com/privacy/).]
 
 ### 4\. SENSITIVE OR SPECIAL CATEGORIES OF INFORMATION
 
@@ -64,7 +79,7 @@ As noted above, we collect information from you in the course of your use of the
 
 ### 6\. HOW DO WE USE THE PERSONAL INFORMATION THAT WE COLLECT?
 
-the PSF collects personal information for the following principal purposes. The list below will state the purpose and the reason for the purpose of collecting your personal information.
+The PSF collects personal information for the following principal purposes. The list below will state the purpose and the reason for the purpose of collecting your personal information.
 
 -   To provide the PyCon website to you
 -   To enroll you for PyCon US-related mailings (opt-in only)
@@ -83,7 +98,7 @@ We do this for our legitimate business purposes, and under certain circumstances
 
 The PSF may share personal information with third parties engaged to assist the PSF in providing services to you or to carry out one or more of the purposes described above. These service providers are prohibited from using your personal information for any purpose other than to provide this assistance and are contractually required to protect personal information disclosed by the PSF and to comply with the general privacy principles described in this Privacy Policy. For example, we share your information with service providers, contractors and sub-contractors to help us provide the website, products, events, and services. For example, we may use a service provider to process payment information or provide analytics. When we use service providers, we provide limited access to your information so that such service provider can perform the tasks on our behalf.
 
-The PSF also shares basic contact information (name and email address) with sponsors if you have explicitly opted in to having your contact information shared with those sponsors.
+The PSF also shares basic contact information (badge name, nickname provided at signup, email address, and country provided during registration) with sponsors if you have explicitly consented to having your contact information shared with those sponsors by permitting them to scan your PyCon badge. You may also choose to share additional information with specific sponsors via the PyCon dashboard.
 
 The PSF reserves the right to disclose and/or transfer personal information to a third party, if the PSF has reason to believe that disclosing personal information is necessary to identify, contact, or bring legal action against someone who may be causing injury to or interference with our rights or property, other website users, or anyone else who could be harmed by such activities. Additionally, the PSF may disclose personal information in response to a subpoena, warrant, or other court order, or when we believe in good faith that a law, regulation, subpoena, warrant or other court order requires or authorizes us to do so, or it is required to respond to an emergency situation.
 
@@ -101,7 +116,7 @@ Unfortunately, the transmission of information via the internet is not completel
 
 If you change your mind on how the PSF discloses or uses your information, or wish to access, correct or update personal information (such as your address), we will endeavor to correct, update or remove the personal data that you give us. Information that you have explicitly made available for unrestricted public access, such as having your name associated with a talk that you provide, may not be able to be deleted.
 
-Citizens of California and citizens of countries in the European Union and European Economic Area may have further rights, including:
+Citizens of California and Virginia, and citizens of countries in the European Union and European Economic Area may have further rights, including:
 
 -   Right of Access to your Personal Information
 -   Right to Rectify your Personal Information